Cross-Site Scripting Vulnerability in Polarion ALM and WebClient
CVE-2021-44478
6.1MEDIUM
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 8 March 2022
What is CVE-2021-44478?
A cross-site scripting vulnerability has been discovered in Polarion ALM and Polarion WebClient for SVN. This vulnerability arises from the inadequate handling of data sent to the web page via the SVN WebClient. Attackers could exploit it by crafting malicious links, which, when accessed by users with administrator privileges, may allow them to execute arbitrary code and extract sensitive information. This poses a significant security risk to users and organizations utilizing the affected versions of the products.
Affected Version(s)
Polarion ALM All versions < V21 R2 P2
Polarion WebClient for SVN All versions